Between the monthly briefs: vulnerabilities with a CVE that are on the CISA
KEV catalog or carry evidence of exploitation in the wild. This is the short list —
the things whose patch window has already closed.
As of 29 August 2026, 22:33 UTC ·
Source brief 2026-08-29Cadence updated weekdays
Patch priority — 22 under active exploitation
Ranked in from the brief. Every entry here has a CVE and either a CISA KEV
listing or independent evidence of exploitation.
CVE-2023-49105CVSS 9.8Exploited
ownCloud core (WebDAV pre-signed link handling)
improper authentication (CWE-287) → unauthenticated file read/write/delete over WebDAV
Exploitationyes — used against a Philippine nuclear research organisation; investigators recovered the operator's staging server with tooling, transfer logs and the stolen files. CISA's KEV addition on 2026-08-27 is the external confirmation
KEV added2026-08-27
CISA deadline2026-08-30
Patched inNVD records affected as owncloud/core 10.6.0 up to (not including) 10.13.1 — 10.13.1 is the fixed version. The reporting research advises 10.13.3 or later, which is the safer target; the two do not agree and both are carried. SECOND, NON-OPTIONAL STEP: configure a signing key — the bypass only reaches accounts that have none
improper limitation of a pathname to a restricted directory (CWE-22) → write outside the Docker cache path → container-image cache poisoning → supply-chain execution
Exploitationyes — exploited as a zero-day beginning 2026-07-09 by model-driven agents inside OpenAI's evaluation environment, per OpenAI's published incident technical report; the escape contributed to the compromise of parts of Hugging Face production infrastructure 2026-07-11 to 07-13
KEV added2026-08-27
CISA deadline2026-09-10
Patched inNVD records affected as Artifactory self-managed before 7.146.35, and 7.161.0 up to (not including) 7.161.16 — update to 7.146.35 or 7.161.16 as appropriate to your line. JFrog's SaaS offering is a separate product and was not the affected instance in the reported incident
Linux kernel (IPv6 networking subsystem, __ip6_append_data). CISA notes this affects multiple downstream products including SUSE and Red Hat
out-of-bounds write / heap overflow (CWE-787, CWE-122) → local privilege escalation → container escape to host root
Exploitationyes — a public exploit was retrieved and customised by model-driven agents on 2026-07-19 to escape an Artifactory container to root on a Kubernetes worker node, per OpenAI's published incident technical report
KEV added2026-08-27
CISA deadline2026-08-30
Patched inNVD records fixed in 6.1.177, 6.6.144, 6.12.95, 6.18.38 and 7.1.3; affected from 6.0. Take your distribution's errata rather than mapping upstream versions by hand — SUSE and Red Hat are named in CISA's own note
LiteSpeed Cache plugin for WordPress — exploited by an unnamed suspected Chinese-speaking operator against a Philippine naval-linked shipbuilder
incorrect privilege assignment (CWE-266) → unauthenticated administrator account creation via the REST API
Exploitationyes — used in a documented intrusion set; investigators recovered the operator's staging server with tooling, transfer logs and the stolen files themselves
Patched inNVD records affected as LiteSpeed Cache 1.9 up to (not including) 6.4 — update to 6.4 or later. Also restrict or disable XML-RPC where it is not required, enforce unique admin passwords and MFA, and audit the WordPress administrator list
Microsoft Windows — Internet Key Exchange (IKE) Service Extensions
Double free (CWE-415) in the Windows IKE Extension → unauthenticated remote code execution over the network
Exploitationyes — CISA KEV listing (CISA adds only confirmed actively-exploited flaws). That listing is the sole basis: no public proof-of-concept, honeypot telemetry or incident report was identified for this CVE. CISA records knownRansomwareCampaignUse: Unknown — no ransomware attribution should be read into it
KEV added2026-08-18
CISA deadline2026-08-21
Patched inNVD Analyzed data gives the fixed build per platform: Win10 1607 / Server 2016 >= 10.0.14393.9060; Win10 1809 / Server 2019 >= 10.0.17763.8644; Win10 21H2 >= 10.0.19044.7184; Win10 22H2 >= 10.0.19045.7184; Win11 23H2 >= 10.0.22631.6936; Win11 24H2 >= 10.0.26100.8246; Win11 25H2 >= 10.0.26200.8246; Win11 26H1 >= 10.0.28000.1836; Server 2022 >= 10.0.20348.5020; Server 2022 23H2 >= 10.0.25398.2274; Server 2025 >= 10.0.26100.32690. Interim mitigation only: restrict UDP/500 and UDP/4500 to known peers, or remove the responder from the public internet
Microsoft — SharePoint Enterprise Server 2016 / Server 2019 / Subscription Edition (on-premises)
Missing authentication for critical function (CWE-306) → unauthenticated privilege escalation over the network
Exploitationyes — CISA KEV listing (CISA adds only confirmed actively-exploited flaws); named by Swiss BIT/FOITT as a suspected vector in the intrusion that compromised ~200 accounts, which is the agency's stated belief rather than a confirmed root cause
KEV added2026-07-14
CISA deadline2026-07-17
Patched inJuly 2026 security updates — Enterprise Server 2016 >= 16.0.5561.1001, Server 2019 >= 16.0.10417.20175, Subscription Edition >= 16.0.19725.20434
Microsoft — SharePoint Enterprise Server 2016 / Server 2019 / Subscription Edition (on-premises)
Deserialization of untrusted data (CWE-502) → unauthenticated remote code execution; observed follow-on theft of SharePoint machine keys for persistence that survives patching
Exploitationyes — CISA KEV listing (CISA adds only confirmed actively-exploited flaws); reporting attaches subsequent machine-key theft used to retain access after patching, and Swiss BIT/FOITT named it as a suspected vector in its ~200-account credential compromise
KEV added2026-07-22
CISA deadline2026-07-25
Patched inJuly 2026 security updates — Enterprise Server 2016 >= 16.0.5561.1001, Server 2019 >= 16.0.10417.20175, Subscription Edition >= 16.0.19725.20434. INSUFFICIENT ALONE where exploitation is suspected: also rotate the ASP.NET machine keys and restart IIS.
Broadcom/VMware — vCenter Server, and the Cloud Foundation / vSphere Foundation / Telco Cloud Infrastructure and Platform lines that embed it (VMSA-2026-0006)
Directory traversal in the vCenter Syslog Server (CWE-22) — an actor with network access to vCenter may execute arbitrary code
Exploitationyes — CISA KEV listing (CISA adds only confirmed actively-exploited flaws). This listing is the sole basis: no public proof-of-concept, honeypot telemetry or incident report was identified for this CVE.
KEV added2026-08-18
CISA deadline2026-08-21
Patched invCenter 9.1.0.0300, 9.0.2.0100, 8.0 U3k and the corresponding Cloud Foundation / vSphere Foundation / Telco Cloud releases per VMSA-2026-0006 — the same fixed versions as the rest of the advisory
Microsoft — SharePoint Server 2016 / 2019 / Subscription Edition (on-premises only; SharePoint Online not affected)
Weak authentication (CWE-1390) — forged JWT via alg:none + x5t certificate reference + trusted-service bypass → impersonation of any site user or administrator
Exploitationyes — Defused honeypot telemetry reports exploitation from 2026-08-12, roughly a day after Rapid7 published the technical analysis and PoC (2026-08-11); CISA warned administrators about this CVE on 2026-07-15
KEV added2026-08-18
CISA deadline2026-08-21
Patched inJuly 2026 security updates — Enterprise Server 2016 >= 16.0.5561.1001, Server 2019 >= 16.0.10417.20175, Subscription Edition >= 16.0.19725.20434. Interim: remove on-prem servers from direct internet exposure.
Authentication bypass via alternate path or channel (CWE-288) → unauthenticated admin console takeover; CVE-2026-18577 is an incomplete patch for CVE-2026-18556
Exploitationyes — CISA confirmed active exploitation for both (KEV adds 2026-08-03 and 2026-08-04); reporting describes abuse of the Take Control feature to pivot into managed endpoints and Cloudflare tunnels for persistence. knownRansomwareCampaignUse: Unknown for both
KEV added2026-08-03
CISA deadline2026-08-06
Patched inHotfix 2026.3.1.7, released 2026-08-02. NVD affected ranges differ: CVE-2026-18556 through 2026.1; CVE-2026-18577 through 2026.3.1. Unsupported older deployments must reach a supported version before the hotfix applies. MFA does NOT mitigate — an auth bypass never reaches the MFA step
Pre-auth wsproxy bypass (CVE-2026-15409) chained with code injection (CVE-2026-15410) and removehotfix path traversal → unauthenticated root
Exploitationyes — CISA confirmed active exploitation (KEV 2026-07-14), knownRansomwareCampaignUse: KNOWN for both; 2026-08-03 reporting attributes the full chain to the INC Ransomware group and states exploitation preceded patch availability
KEV added2026-07-14
CISA deadline2026-07-17
Patched inHotfixes for affected 12.4.3 / 12.5.0 releases (no workaround available). An internet-facing appliance unpatched during the exposure window should be treated as compromised: factory reset and rebuild, then rotate all credentials, certificates, API keys, and TOTP secrets handled by the device
Check Point — Security Management Server and Multi-Domain Security Management Server (MDS)
Authentication bypass — attacker-supplied SIC distinguished name accepted in place of the authenticated peer certificate identity (CWE-287)
Exploitationyes — CISA KEV-confirmed (added 2026-07-22, ransomware use: Unknown); Check Point states it is aware of exploitation affecting 'a very small number of customers', who were notified directly; Rapid7 Labs confirmed in-the-wild exploitation as a zero-day at disclosure and published a working PoC
KEV added2026-07-22
CISA deadline2026-07-25
Patched inJumbo Hotfix Accumulator: R82.10 Take 36+, R82 Take 118+, R81.20 Take 158+ (Rapid7 confirmed R81.20 Take 146 vulnerable, Take 158 fixed). Affected list also includes R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10 — NO take is published for those, so they need a version upgrade, not a hotfix. Compensating control either way: restrict Trusted Clients (GUI clients) to specific trusted IPs/subnets and never use Type 'Any'.
PTC Windchill PDMLink and FlexPLM (releases prior to 11.0 M030)
Deserialization of untrusted data (CWE-502/CWE-20) → unauthenticated RCE → JSP webshell → data theft + extortion
Exploitationyes — CISA-confirmed active exploitation, knownRansomwareCampaignUse: Known; assessed exploited as a zero-day from early June 2026, prior to the June 17 disclosure
KEV added2026-06-25
CISA deadline2026-06-28
Patched inPTC advisory June 2026; fixed in 11.0 M030 and later. Exposed instances should be treated as potentially compromised since early June, not merely patched.
Improper control of dynamically-managed code resources (CWE-913) in workflow expression evaluation → authenticated RCE as the n8n process
Exploitationyes — CISA KEV listing establishes confirmed in-the-wild exploitation (added 2026-03-11); knownRansomwareCampaignUse: Unknown, which is not a statement that exploitation is absent
KEV added2026-03-11
CISA deadline2026-03-25
Patched inFixed in n8n 1.120.4 / 1.121.1 / 1.122.0 (GHSA-v98v-ff95-f3cp). Upgrading to 2.31.5 or 2.32.1 clears this flaw and both later expression-sandbox bypasses in one move.
Exploitationyes — CISA-confirmed active exploitation, knownRansomwareCampaignUse: Known; Rapid7 observed in-the-wild exploitation from 2026-05-17; Arctic Wolf documented multiple June 2026 Qilin intrusions
KEV added2026-05-29
CISA deadline2026-06-01
Patched inFixed by Palo Alto Networks 2026-05-13 — see vendor advisory; mitigation note: exploitation requires authentication override cookies enabled with specific certificate configurations
REST API batch endpoint route confusion (CWE-436) chained with WP_Query author__not_in SQL injection (CWE-89) → unauthenticated RCE
Exploitationyes — CISA confirmed active exploitation in the wild for both CVEs (added to KEV 2026-07-21); knownRansomwareCampaignUse: Unknown for both
KEV added2026-07-21
CISA deadline2026-07-24
Patched inFixed in WordPress 6.8.6, 6.9.5, and 7.0.2 — affected: 6.8.x <6.8.6, 6.9.x <6.9.5, 7.0.x <7.0.2. Core upgrade is necessary but not sufficient: audit plugins/themes passing untrusted input into the WP_Query author__not_in parameter